SV-268165r1131135_rule
V-268165
SRG-OS-000468-GPOS-00212
ANIX-00-001740
CAT II
10
Configure NixOS to audit attempts to delete security objects.
Add the following Nix code to the NixOS Configuration, usually located in /etc/nixos/configuration.nix or /etc/nixos/flake.nix:
security.audit.rules = [
"-a always,exit -F path=/run/current-system/sw/bin/chage -F perm=x -F auid>=1000 -F auid!=unset -k privileged-chage"
"-a always,exit -F path=/run/current-system/sw/bin/chcon -F perm=x -F auid>=1000 -F auid!=unset -k perm_mod"
];
Rebuild and switch to the new NixOS configuration:
$ sudo nixos-rebuild switch
Verify that NixOS generates audit records when successful/unsuccessful attempts to delete security objects occur with the following command:
$ sudo auditctl -l | grep /bin/ch
-a always,exit -S all -F path=/run/current-system/sw/bin/chage -F perm=x -F auid>=1000 -F auid!=-1 -k privileged-chage
-a always,exit -S all -F path=/run/current-system/sw/bin/chcon -F perm=x -F auid>=1000 -F auid!=-1 -k perm_mod
If the command does not return an audit rule for "chage" and "chcon", this is a finding.
V-268165
False
ANIX-00-001740
Verify that NixOS generates audit records when successful/unsuccessful attempts to delete security objects occur with the following command:
$ sudo auditctl -l | grep /bin/ch
-a always,exit -S all -F path=/run/current-system/sw/bin/chage -F perm=x -F auid>=1000 -F auid!=-1 -k privileged-chage
-a always,exit -S all -F path=/run/current-system/sw/bin/chcon -F perm=x -F auid>=1000 -F auid!=-1 -k perm_mod
If the command does not return an audit rule for "chage" and "chcon", this is a finding.
M
5658